However, if the QID covers several CVE's....say 10 for a round number, and 9 are already patched / remediated in our infrastructure (including the CVE I'm interested in)....isn't the scan giving me false data?

How can I tell what actual CVE is not remediated i.e. is it the actual CVE I'm interested in?

Maybe I'm not understanding this correctly so would appreciate some guidance!

With out knowing more about the particular CVE and speaking generally:

The 'Results' of the QID for that Asset (in the vuln report) should tell you what Qualys found that made it register that QID as well as what it was expecting. There are usually detailed instructions in the "Solution" area.